keybase / keybase/keybase-issues
Twitter verification by ID, not username
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
A friend of mine recently [re-verified their twitter account for the third time](https://twitter.com/enbygorawr/status/516464525441110016). This is because the verification process has us sign our Twitter username, and when it changes, the signature has to be redone.
However, Twitter uses a `user_id` to enable username changes, and this ID never changes. It would be preferable, then, if the verification used that ID instead of the username, ensuring that any username change need not be followed by yet another keybase proof for essentially the same account.
As a security bonus, is there currently a mechanism that prevents someone grabbing another's usual twitter handle while they've changed temporarily (which may be done around events, like the upcoming :ghost: Halloween :jack_o_lantern:), sign that with keybase, and then be able to display, forever, a "wrong" identity on their keybase profile? Sure, manual verification of the proof tweet could alleviate consequences, but wouldn't it be better to simply sign the ID, thus proving ownership of the twitter account, no matter what handle it uses at any given time?
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the existing Twitter verification flow and how proofs identify accounts; the issue names no files or tests. Done would mean verification remains tied to Twitter's stable user_id across username changes and does not allow a temporary handle change to produce a lasting wrong identity.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100